Skip to content

Using Extractor to replace Authorization: Bearer tokens in scanner causes full PC lockup, requiring hard-reset #5

@mdalin

Description

@mdalin

When using Extractor to auto-replace Authorization: Bearer tokens, I can get it to work fine while using Repeater, but as soon as I launch a scan, my entire laptop goes into a hard lockup. No mouse movement, no keyboard response. Only way to recover is to do a hard, power-button reset. This usually winds up corrupting my Burp project file. I've attempted it using Burp 1.75, as well as 2020.4. I've disabled all other extensions, and made sure I'm only scanning a single URL which returns a small amount of JSON. Attached are sanitized requests and responses that were used to extract/inject the parameter, as well as the regexes used.

ExtractorFail.txt

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions